Bomka manual removal:
Kill processes:
icqchk.exe, ietool.exe, iewatch.exe, kpsf.exe, videocodec3_05b_[X].exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\IEAgent update check
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runapp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\icqupd
HKEY_CLASSES_ROOT\Kaboom.IEagent
HKEY_CLASSES_ROOT\Kaboom.IEagent.1
HKEY_CLASSES_ROOT\Watcher.GoogleTracker
HKEY_CLASSES_ROOT\Watcher.GoogleTracker.1
HKEY_CLASSES_ROOT\CLSID\{4BC9A7AC-2329-49D0-B07F-5FE484029DC2
HKEY_CLASSES_ROOT\CLSID\{A853979C-2A9A-4ACB-8975-5740A7E26CB4}
HKEY_CLASSES_ROOT\CLSID\{CC56A1F3-9B83-45FF-8CB6-D58959492F0F}
HKEY_CLASSES_ROOT\Interface\{88B67E52-A8D4-44AF-A199-DEE96469B7AF}
HKEY_CLASSES_ROOT\Interface\{BAA919E5-FD47-4D7E-95AB-5B2CDA493358}
HKEY_CLASSES_ROOT\Interface\{D861BD5E-E1E7-4E5E-AB15-CB347FBDBC6D}
HKEY_CLASSES_ROOT\TypeLib\{023E6659-1A0A-4724-9273-66EA06A82C98}
HKEY_CLASSES_ROOT\TypeLib\{B73EF4A8-B8B1-4683-8D21-AA1C1A46CAD7}
HKEY_CLASSES_ROOT\TypeLib\{E0C0FC76-CC5E-46E2-B77A-4C2ADD965B9F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4BC9A7AC-2329-49D0-B07F-5FE484029DC2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A853979C-2A9A-4ACB-8975-5740A7E26CB4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC56A1F3-9B83-45FF-8CB6-D58959492F0F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IEAgent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SUW
Delete files:icqchk.exe, ietool.exe, iewatch.exe, kpsf.exe, videocodec3_05b_[X].exe, gtrack.dll, kaboom.dll, msx.dll, kpsf.sys
Misc:[X] is a certain number.
Files ietool.exe and videocodec3_05b_[X].exe install Bomka. These files are downloaded from the Internet.
All Bomka files can be found in default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.
Post Comment: